<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro Distribution Mode in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Distribution-Mode/m-p/97968#M301</link>
    <description>&lt;P&gt;Turns out L4 is enabled by default and recommended by TAC to disable unless doing heavy NAT or SGMs are not balanced.&amp;nbsp; DNS issues resolved.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2020 01:05:16 GMT</pubDate>
    <dc:creator>Raj_Khatri</dc:creator>
    <dc:date>2020-10-01T01:05:16Z</dc:date>
    <item>
      <title>Maestro Distribution Mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Distribution-Mode/m-p/97759#M300</link>
      <description>&lt;P&gt;Has anyone faced issues with outbound DNS on R80.20SP with 2&amp;nbsp;&lt;SPAN&gt;MHO-140 + 2 members&lt;/SPAN&gt;?&amp;nbsp; We have multiple private interfaces and performing hide NAT for traffic leaving our external interface - pretty standard.&amp;nbsp; We have noticed very slow and unresponsive DNS queries and lookups.&lt;/P&gt;&lt;P&gt;The default distribution mode is "manual-general" and after reading&amp;nbsp;sk108842, when performing Hide NAT, the external interface should be configured as "network" instead of "user"&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108842&amp;amp;partition=Advanced&amp;amp;product=Scalable" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108842&amp;amp;partition=Advanced&amp;amp;product=Scalable&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After making the change to "auto-topology" and setting the external interface to "network,"&amp;nbsp;DNS queries are back to normal.&amp;nbsp; Still experiencing odd DNS issues from certain private segments when pointing to an internal F5 VIP (using external forwarders), but wondering if anybody else has faced similar issues.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Before&lt;/U&gt;:&lt;BR /&gt;eth1-x :policy-internal&lt;BR /&gt;eth2-x: policy-external&lt;/P&gt;&lt;P&gt;&lt;U&gt;After&lt;/U&gt;:&lt;BR /&gt;eth1-x :manual-internal&lt;BR /&gt;eth2-x: manual-external&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 00:45:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Distribution-Mode/m-p/97759#M300</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2020-09-29T00:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Distribution Mode</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Distribution-Mode/m-p/97968#M301</link>
      <description>&lt;P&gt;Turns out L4 is enabled by default and recommended by TAC to disable unless doing heavy NAT or SGMs are not balanced.&amp;nbsp; DNS issues resolved.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 01:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Distribution-Mode/m-p/97968#M301</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2020-10-01T01:05:16Z</dc:date>
    </item>
  </channel>
</rss>

